Ledger's Connect Kit library suffered a security breach resulting in the theft of approximately $484,000 from user wallets. According to onchain intelligence firm Lookonchain, the attacker siphoned funds to an Ethereum address. Ledger confirmed that a former employee fell victim to a phishing attack, compromising their NPMJS account. The attacker used this access to upload malicious versions (1.1.5 through 1.1.7) of the Ledger Connect Kit, which manipulated a fraudulent Walletconnect project to redirect user funds to the hacker's wallet.
Timeline and Response
Ledger deployed a fix within 40 minutes of becoming aware of the breach, but the malicious file remained active for approximately five hours. The actual fund-draining window was under two hours. Ledger collaborated with Walletconnect to disable the rogue project and subsequently released the verified Ledger Connect Kit version 1.1.8, which is now being automatically distributed. The company advised developers to wait 24 hours before resuming use of the Connect Kit.
To prevent future incidents, Ledger restricted all development team accounts on NPM to read-only access for the Connect Kit, preventing direct package updates. Tether has frozen the attacker's address, which is now visible through Chainalysis software. Ledger disclosed the hacker's wallet address: 0x658729879fca881d9526480b82ae00efc54b5c2d, which still holds $254K at the time of writing.
Security Recommendations and Industry Impact
Ledger emphasized the importance of Clear Signing and recommended using an additional Ledger mint wallet or manual transaction parsing for blind signing. This breach has impacted numerous decentralized applications (dApps) that rely on the Connect Kit, highlighting the critical need for supply chain security in the crypto industry. Ledger is actively engaging with affected customers, working with law enforcement, and analyzing the exploit to prevent future attacks.

